Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
65b5d95937 | ||
|
|
89a8edad88 | ||
|
|
283c1d77b4 | ||
|
|
f060f917a0 | ||
|
|
704740182a | ||
|
|
a61860fcb3 | ||
|
|
340d9b5245 | ||
|
|
5d02fa5769 | ||
|
|
526b2df8ea | ||
|
|
4f9629b089 |
@@ -3,9 +3,6 @@ TALLYNOTE_PORT=3000
|
||||
TALLYNOTE_DATA_DIR=./data
|
||||
TALLYNOTE_TIMEZONE=Asia/Shanghai
|
||||
TALLYNOTE_PUBLIC_ORIGIN=http://127.0.0.1:3000
|
||||
# Optional additional browser Origins for an explicit reverse-proxy alias.
|
||||
# Keep the primary public origin above and list only trusted HTTPS origins.
|
||||
# TALLYNOTE_ALLOWED_ORIGINS=https://tally.example.com,https://tally.internal.example
|
||||
TALLYNOTE_TRUST_PROXY=false
|
||||
TALLYNOTE_COOKIE_SECURE=false
|
||||
# Set TALLYNOTE_HOST=0.0.0.0 and the server's real IP Origin for direct
|
||||
|
||||
@@ -17,6 +17,10 @@ jobs:
|
||||
steps:
|
||||
- name: Checkout tag
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
# Release notes are derived from the previous version tag. A shallow
|
||||
# checkout would leave only the synthetic release commit available.
|
||||
fetch-depth: 0
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
@@ -29,7 +33,10 @@ jobs:
|
||||
test "$(node -p 'require("./package.json").version')" = "${GITHUB_REF_NAME#v}"
|
||||
pnpm install --frozen-lockfile
|
||||
pnpm check
|
||||
pnpm test
|
||||
# better-sqlite3 is a native addon; a single Vitest worker avoids a
|
||||
# Node cleanup race observed on the hosted runner while preserving
|
||||
# the complete test suite.
|
||||
pnpm test -- --maxWorkers=1 --minWorkers=1
|
||||
pnpm test:installer
|
||||
- name: Build Linux release
|
||||
run: pnpm release:build "${GITHUB_REF_NAME#v}" ./release
|
||||
|
||||
@@ -140,7 +140,7 @@ curl --proto '=https' --tlsv1.2 -fsSL https://git.awaioi.com/awaioi/TallyNote/ra
|
||||
|
||||
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
|
||||
|
||||
公网反代必须使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。登录和所有写入请求会校验浏览器 `Origin`;反代必须原样转发 `Origin`,且访问地址必须与 `TALLYNOTE_PUBLIC_ORIGIN` 完全一致。若确实需要多个受信任域名,可用 `TALLYNOTE_ALLOWED_ORIGINS=https://a.example.com,https://b.example.com` 显式列出(只写 Origin,不含路径),不要把它设为任意来源。
|
||||
公网反代推荐使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。反代只需把域名转发到 TallyNote 端口并保留 `Host`、`X-Forwarded-Proto`;应用不会因为代理缺少或改写浏览器 `Origin` 而拦截登录。已认证写请求仍使用会话 Cookie 与 CSRF 令牌保护。
|
||||
|
||||
### 构建发布包
|
||||
|
||||
|
||||
+4
-2
@@ -12,6 +12,8 @@ TallyNote 的发布包必须在目标 Linux 架构上构建。`better-sqlite3`
|
||||
2. 由 `scripts/publish-gitea-release.sh` 计算所有归档的 `SHA256SUMS`。
|
||||
3. 如果提供 Ed25519 私钥则生成 `SHA256SUMS.sig`,通过 Gitea Releases API 创建/复用对应 Release,并幂等上传归档、清单和可选签名。
|
||||
|
||||
发布脚本会根据当前 tag 与上一个版本 tag 之间的真实 Git 提交自动生成 Release 正文,按“新增功能、问题修复、优化与重构、文档与测试”分类,并以 Markdown 写入 Gitea。Gitea 页面会渲染这些标题和列表;更新中心读取同一份正文后再进行安全的 Markdown 子集渲染,不会显示 Markdown 源代码。旧版本曾使用单行占位正文 `TallyNote <版本>`,新版本发布时不会再使用该占位内容。
|
||||
|
||||
在仓库的 Actions secrets 配置:
|
||||
|
||||
- `GITEA_TOKEN`:仅授予当前仓库 Release 写权限的 token。
|
||||
@@ -28,7 +30,7 @@ GITEA_TOKEN=... \
|
||||
./scripts/publish-gitea-release.sh v1.1.2 ./release
|
||||
```
|
||||
|
||||
发布资产名称必须包含当前平台,例如 `tallynote-1.1.2-linux-x64-glibc.tar.gz`。同一个 Release 只保留一个 `SHA256SUMS`;有签名时再保留一个 `SHA256SUMS.sig`,签名覆盖清单完整原文。
|
||||
发布资产名称必须包含当前平台,例如 `tallynote-1.1.2-linux-x64-glibc.tar.gz`。构建脚本会同时生成完整安装包和轻量更新包:`tallynote-1.1.2-linux-x64-glibc.tar.gz` 用于首次安装,`tallynote-1.1.2-linux-x64-glibc.update-<锁文件 SHA256>.tar.gz` 仅用于复用现有运行时的后台更新。同一个 Release 只保留一个 `SHA256SUMS`;有签名时再保留一个 `SHA256SUMS.sig`,签名覆盖清单完整原文。
|
||||
|
||||
## curl 安装
|
||||
|
||||
@@ -104,7 +106,7 @@ sudo /usr/local/sbin/tallynote-uninstall
|
||||
|
||||
将环境文件中的 `TALLYNOTE_UPDATE_STRATEGY=systemd`、`TALLYNOTE_UPDATE_METADATA_URL` 和 `TALLYNOTE_UPDATE_ALLOWED_HOSTS` 配好后,后台“系统更新”会读取 Gitea 的 `/api/v1/repos/<owner>/<repo>/releases/latest`。检查结果只显示当前平台匹配且通过 SHA-256 校验的资产;如果配置了 `TALLYNOTE_UPDATE_PUBLIC_KEY_FILE` 并启用签名要求,再额外验证 Ed25519 签名。
|
||||
|
||||
后台更新分为两个明确阶段。管理员先在“系统更新”读取最新 Release 的版本号、发布时间和更新说明,点击“下载更新包”;root 更新器会在主服务继续运行时下载、校验 SHA-256、解包并暂存。页面显示“下载完成,等待应用”后,管理员再点击“立即更新”。应用阶段才会短暂停止服务、备份数据、切换 release、启动并执行健康检查;页面显示重启倒计时并自动重试连接。浏览器只提交版本号、任务 ID 和确认标志,不能提交 URL 或文件路径。
|
||||
后台更新分为两个明确阶段。管理员先在“系统更新”读取最新 Release 的版本号、发布时间和更新说明,点击“下载更新包”;当前安装如果存在匹配的锁文件指纹,更新器会自动选择轻量 `update-<锁文件 SHA256>` 资产,仅下载 `dist`、迁移和版本元数据,并复用当前版本的 Node 与生产依赖;如果运行时指纹不匹配或轻量包不可用,则自动选择完整安装包。root 更新器会在主服务继续运行时下载、校验 SHA-256、解包并暂存。页面显示“下载完成,等待应用”后,管理员再点击“立即更新”。应用阶段才会短暂停止服务、备份数据、切换 release、启动并执行健康检查;页面显示重启倒计时并自动重试连接。浏览器只提交版本号、任务 ID 和确认标志,不能提交 URL 或文件路径。
|
||||
|
||||
Web 进程把受保护的任务文件交给 root 的 `tallynote-update.path`/`tallynote-update.service`,root runner 会重新读取配置源并验证 metadata、清单和暂存目录,不信任队列文件中的 URL 或摘要。切换失败或健康检查失败会恢复旧版本;手动回滚:
|
||||
|
||||
|
||||
@@ -1460,7 +1460,6 @@ main() {
|
||||
elif [[ -n "${TALLYNOTE_PUBLIC_ORIGIN+x}" ]]; then
|
||||
set_env_key TALLYNOTE_PUBLIC_ORIGIN "$INSTALL_PUBLIC_ORIGIN"
|
||||
fi
|
||||
if [[ -n "${TALLYNOTE_ALLOWED_ORIGINS+x}" ]]; then set_env_key TALLYNOTE_ALLOWED_ORIGINS "$TALLYNOTE_ALLOWED_ORIGINS"; fi
|
||||
if [[ -n "${TALLYNOTE_ALLOW_INSECURE_HTTP+x}" ]]; then set_env_key TALLYNOTE_ALLOW_INSECURE_HTTP "$INSTALL_ALLOW_INSECURE_HTTP"; fi
|
||||
ensure_env_key TALLYNOTE_INSTALL_PREFIX "$PREFIX"
|
||||
ensure_env_key TALLYNOTE_DATA_DIR "$DATA_DIR"
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "tallynote",
|
||||
"version": "1.1.21",
|
||||
"version": "1.1.29",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"packageManager": "pnpm@9.0.6",
|
||||
|
||||
@@ -27,7 +27,11 @@ pnpm build
|
||||
stage=$(mktemp -d)
|
||||
trap 'rm -rf "$stage"' EXIT
|
||||
mkdir -p "$stage/dist" "$stage/migrations" "$stage/bin" "$stage/scripts" "$stage/systemd" "$stage/runtime/bin"
|
||||
cp -a dist/. "$stage/dist/"
|
||||
# Copy only the production build outputs. In particular, do not carry a
|
||||
# stale dist/web-next directory from a previous local preview build.
|
||||
cp -a dist/server "$stage/dist/"
|
||||
cp -a dist/shared "$stage/dist/"
|
||||
cp -a dist/web "$stage/dist/"
|
||||
cp -a migrations/. "$stage/migrations/"
|
||||
cp package.json pnpm-lock.yaml "$stage/"
|
||||
cp -a bin/. "$stage/bin/"
|
||||
@@ -46,6 +50,26 @@ find "$stage" -type l -delete
|
||||
mkdir -p "$OUT_DIR"
|
||||
archive="$OUT_DIR/tallynote-${VERSION}-linux-${ARCH}-${LIBC}.tar.gz"
|
||||
tar -C "$stage" -czf "$archive" --owner=0 --group=0 --numeric-owner .
|
||||
|
||||
# The application-only asset is used by the online updater. It deliberately
|
||||
# excludes the stable runtime (Node and production dependencies), systemd
|
||||
# helpers and installer files; the updater overlays it on the currently
|
||||
# installed, already-validated runtime before atomically switching releases.
|
||||
app_stage=$(mktemp -d)
|
||||
trap 'rm -rf "$stage" "$app_stage"' EXIT
|
||||
mkdir -p "$app_stage/dist" "$app_stage/migrations" "$app_stage/bin" "$app_stage/scripts" "$app_stage/systemd"
|
||||
cp -a "$stage/dist/server" "$app_stage/dist/"
|
||||
cp -a "$stage/dist/shared" "$app_stage/dist/"
|
||||
cp -a "$stage/dist/web" "$app_stage/dist/"
|
||||
cp -a "$stage/migrations/." "$app_stage/migrations/"
|
||||
cp -a "$stage/bin/." "$app_stage/bin/"
|
||||
cp -a "$stage/scripts/." "$app_stage/scripts/"
|
||||
cp -a "$stage/systemd/." "$app_stage/systemd/"
|
||||
cp "$stage/package.json" "$app_stage/package.json"
|
||||
cp "$stage/uninstall.sh" "$app_stage/uninstall.sh"
|
||||
runtime_hash=$(sha256sum pnpm-lock.yaml | awk '{print $1}')
|
||||
app_archive="$OUT_DIR/tallynote-${VERSION}-linux-${ARCH}-${LIBC}.update-${runtime_hash}.tar.gz"
|
||||
tar -C "$app_stage" -czf "$app_archive" --owner=0 --group=0 --numeric-owner .
|
||||
# Keep the sidecar useful when a caller builds more than one architecture into
|
||||
# the same directory. The publishing script recomputes this list immediately
|
||||
# before signing, so stale or hand-edited entries can never reach a Release.
|
||||
|
||||
@@ -24,6 +24,7 @@ DRY_RUN=0
|
||||
AUTH_CONFIG=''
|
||||
SUMS_TMP=''
|
||||
SIG_TMP=''
|
||||
RELEASE_NOTES_TMP=''
|
||||
SIGNATURE_GENERATED=0
|
||||
|
||||
usage() {
|
||||
@@ -43,6 +44,81 @@ EOF
|
||||
die() { printf 'release publisher: %s\n' "$*" >&2; exit 1; }
|
||||
log() { printf 'release publisher: %s\n' "$*"; }
|
||||
|
||||
generate_release_notes() {
|
||||
local current=${TAG#v} previous='' subject kind line count=0
|
||||
local -a commits
|
||||
commits=()
|
||||
|
||||
# A workflow checks out the tag with history. Prefer an explicitly supplied
|
||||
# notes file for mirrors, then derive notes from the immutable tag range.
|
||||
if [[ -n "${TALLYNOTE_RELEASE_NOTES_FILE:-}" && -f "$TALLYNOTE_RELEASE_NOTES_FILE" ]]; then
|
||||
# Read at most the API's bounded notes size without a pipe that can turn a
|
||||
# deliberately truncated input into a SIGPIPE failure under pipefail.
|
||||
LC_ALL=C awk 'BEGIN { remaining = 65536 } { if (remaining <= 0) exit; line=$0; gsub(/[[:cntrl:]]/, "", line); bytes=length(line)+1; if (bytes > remaining) { print substr(line, 1, remaining); exit } print line; remaining-=bytes }' "$TALLYNOTE_RELEASE_NOTES_FILE"
|
||||
return
|
||||
fi
|
||||
|
||||
if command -v git >/dev/null 2>&1 && git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] || continue
|
||||
[[ "$line" == "v${current}" ]] && continue
|
||||
previous="$line"
|
||||
break
|
||||
done < <(git tag --sort=-version:refname --list 'v*')
|
||||
if [[ -n "$previous" && "$previous" != "v${current}" ]]; then
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] && commits+=("$line")
|
||||
done < <(git log --format='%s' "${previous}..${TAG}")
|
||||
else
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] && commits+=("$line")
|
||||
done < <(git log -n 30 --format='%s' "$TAG")
|
||||
fi
|
||||
fi
|
||||
|
||||
printf '# TallyNote %s\n\n' "$current"
|
||||
if [[ -n "$previous" ]]; then
|
||||
printf '> 从 `%s` 到 `%s` 的变更\n\n' "$previous" "v${current}"
|
||||
else
|
||||
printf '> 本版本变更\n\n'
|
||||
fi
|
||||
|
||||
local -a features fixes improvements docs other
|
||||
features=(); fixes=(); improvements=(); docs=(); other=()
|
||||
for subject in "${commits[@]-}"; do
|
||||
# Do not expose merge noise or the synthetic release commit in user notes.
|
||||
[[ "$subject" != Merge\ * && "$subject" != release:* ]] || continue
|
||||
kind=${subject%%:*}
|
||||
if [[ "$subject" == *:* ]]; then subject=${subject#*: }; fi
|
||||
subject=${subject# }
|
||||
[[ -n "$subject" ]] || continue
|
||||
case "$kind" in
|
||||
feat|feature) features+=("$subject") ;;
|
||||
fix|bugfix) fixes+=("$subject") ;;
|
||||
refactor|perf|style|improvement) improvements+=("$subject") ;;
|
||||
docs|doc|test|tests) docs+=("$subject") ;;
|
||||
*) other+=("$subject") ;;
|
||||
esac
|
||||
done
|
||||
|
||||
print_group() {
|
||||
local title=$1; shift
|
||||
local item
|
||||
(($# > 0)) || return 0
|
||||
printf '## %s\n\n' "$title"
|
||||
for item in "$@"; do printf -- '- %s\n' "$item"; done
|
||||
printf '\n'
|
||||
}
|
||||
((${#features[@]})) && print_group '新增功能' "${features[@]}"
|
||||
((${#fixes[@]})) && print_group '问题修复' "${fixes[@]}"
|
||||
((${#improvements[@]})) && print_group '优化与重构' "${improvements[@]}"
|
||||
((${#docs[@]})) && print_group '文档与测试' "${docs[@]}"
|
||||
((${#other[@]})) && print_group '其他变更' "${other[@]}"
|
||||
if (( ${#features[@]} + ${#fixes[@]} + ${#improvements[@]} + ${#docs[@]} + ${#other[@]} == 0 )); then
|
||||
printf '本版本包含内部维护更新。\n'
|
||||
fi
|
||||
}
|
||||
|
||||
validate_semver() {
|
||||
local value=$1 prerelease part
|
||||
[[ "$value" =~ ^v?(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(-[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?(\+[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?$ ]] || return 1
|
||||
@@ -128,7 +204,8 @@ fi
|
||||
[[ "$CURL_BIN" != *[[:space:]]* && "$CURL_BIN" != *[[:cntrl:]]* ]] || die 'curl executable path is invalid'
|
||||
command -v "$CURL_BIN" >/dev/null 2>&1 || die 'curl is required'
|
||||
|
||||
assets=()
|
||||
full_assets=()
|
||||
update_assets=()
|
||||
for file in "$ASSET_DIR"/*.tar.gz; do
|
||||
[[ -f "$file" && ! -L "$file" ]] || continue
|
||||
name=$(basename -- "$file")
|
||||
@@ -136,9 +213,16 @@ for file in "$ASSET_DIR"/*.tar.gz; do
|
||||
asset_version=${name#tallynote-}
|
||||
asset_version=${asset_version%%-linux-*}
|
||||
[[ "$asset_version" == "${TAG#v}" ]] || die "release asset version does not match tag: $name"
|
||||
assets+=("$file")
|
||||
if [[ "$name" =~ \.update-[a-f0-9]{64}\.tar\.gz$ ]]; then
|
||||
update_assets+=("$file")
|
||||
else
|
||||
full_assets+=("$file")
|
||||
fi
|
||||
done
|
||||
assets=("${full_assets[@]}")
|
||||
if ((${#update_assets[@]})); then assets+=("${update_assets[@]}"); fi
|
||||
(( ${#assets[@]} > 0 )) || die 'no .tar.gz release asset found'
|
||||
(( ${#full_assets[@]} > 0 )) || die 'no full release asset found'
|
||||
|
||||
SUMS_FILE="$ASSET_DIR/SHA256SUMS"
|
||||
SIG_FILE="$ASSET_DIR/SHA256SUMS.sig"
|
||||
@@ -161,6 +245,7 @@ cleanup() {
|
||||
if [[ -n "$AUTH_CONFIG" ]]; then rm -f -- "$AUTH_CONFIG"; fi
|
||||
if [[ -n "$SUMS_TMP" ]]; then rm -f -- "$SUMS_TMP"; fi
|
||||
if [[ -n "$SIG_TMP" ]]; then rm -f -- "$SIG_TMP"; fi
|
||||
if [[ -n "$RELEASE_NOTES_TMP" ]]; then rm -f -- "$RELEASE_NOTES_TMP"; fi
|
||||
}
|
||||
trap cleanup EXIT
|
||||
if [[ -n "$SIGNING_KEY_FILE" ]]; then
|
||||
@@ -196,6 +281,13 @@ command -v jq >/dev/null 2>&1 || die 'jq is required for Gitea API publishing'
|
||||
write_auth_config
|
||||
unset TOKEN
|
||||
|
||||
# Keep the release body deterministic and human-readable. Gitea renders this
|
||||
# Markdown in the Release page; the update API later exposes the same body as
|
||||
# text for the safe client-side Markdown renderer.
|
||||
RELEASE_NOTES_TMP=$(mktemp)
|
||||
generate_release_notes > "$RELEASE_NOTES_TMP"
|
||||
release_notes=$(<"$RELEASE_NOTES_TMP")
|
||||
|
||||
api_curl() {
|
||||
"$CURL_BIN" --proto '=https' --tlsv1.2 --fail --silent --show-error --connect-timeout 15 --max-time 120 \
|
||||
--config "$AUTH_CONFIG" "$@"
|
||||
@@ -213,8 +305,17 @@ release_json=$(mktemp)
|
||||
status=$(api_curl_status --max-time 30 -o "$release_json" -w '%{http_code}' "$API_ROOT/repos/$repo_path/releases/tags/$TAG") || die '无法读取 Gitea Release'
|
||||
if [[ "$status" == 200 ]]; then
|
||||
release_id=$(jq -r '.id // empty' "$release_json")
|
||||
existing_body=$(jq -r '.body // ""' "$release_json")
|
||||
# Older releases used a one-line placeholder. Upgrade that placeholder when
|
||||
# a tag is republished, while leaving deliberately authored release notes
|
||||
# untouched.
|
||||
if [[ "$existing_body" == "TallyNote $TAG" || -z "$existing_body" ]]; then
|
||||
patch_body=$(jq -cn --arg body "$release_notes" '{body:$body}')
|
||||
patch_status=$(api_curl_status -X PATCH -H 'Content-Type: application/json' -d "$patch_body" -o /dev/null -w '%{http_code}' "$API_ROOT/repos/$repo_path/releases/$release_id") || die '无法更新 Gitea Release 日志'
|
||||
[[ "$patch_status" == 2* ]] || die "无法更新 Gitea Release 日志(HTTP $patch_status)"
|
||||
fi
|
||||
elif [[ "$status" == 404 ]]; then
|
||||
body=$(jq -cn --arg tag "$TAG" --arg name "$TAG" --arg body "TallyNote $TAG" '{tag_name:$tag,name:$name,body:$body,draft:false,prerelease:false}')
|
||||
body=$(jq -cn --arg tag "$TAG" --arg name "$TAG" --arg body "$release_notes" '{tag_name:$tag,name:$name,body:$body,draft:false,prerelease:false}')
|
||||
create_status=$(api_curl_status -H 'Content-Type: application/json' -d "$body" -o "$release_json" -w '%{http_code}' "$API_ROOT/repos/$repo_path/releases") || die '无法创建 Gitea Release'
|
||||
if [[ "$create_status" == 2* ]]; then
|
||||
release_id=$(jq -r '.id // empty' "$release_json")
|
||||
|
||||
+9
-15
@@ -648,19 +648,6 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
return payload;
|
||||
});
|
||||
|
||||
app.addHook("onRequest", async (request) => {
|
||||
if (!unsafeMethods.has(request.method) || !request.url.startsWith("/api/")) return;
|
||||
const origin = request.headers.origin;
|
||||
const allowed = new Set(config.allowedOrigins);
|
||||
if (!config.isProduction) {
|
||||
allowed.add("http://127.0.0.1:5173");
|
||||
allowed.add("http://localhost:5173");
|
||||
}
|
||||
if (typeof origin !== "string" || !allowed.has(origin)) {
|
||||
throw new AppError(403, "ORIGIN_FORBIDDEN", "请求来源不受信任");
|
||||
}
|
||||
});
|
||||
|
||||
app.setErrorHandler((error, request, reply) => {
|
||||
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
|
||||
if (error instanceof ZodError) {
|
||||
@@ -943,6 +930,11 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
reply.header("Cache-Control", "no-store");
|
||||
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||
const cached = publicCheckFromCache(database.sqlite, config);
|
||||
// Status is a live control surface, not an update history endpoint.
|
||||
// Terminal failures/cancellations from a previous attempt must not be
|
||||
// replayed as if the operator had just started an update. They remain in
|
||||
// the database/audit log, while this endpoint exposes only an actionable
|
||||
// task (or the latest successful completion for confirmation).
|
||||
const row = database.sqlite.prepare(`
|
||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||
@@ -950,8 +942,10 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||
download_speed_bps AS downloadSpeedBps,
|
||||
requested_at AS applyQueuedAt
|
||||
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
|
||||
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||
FROM update_jobs
|
||||
WHERE admin_id=? AND status IN (${[...ACTIVE_UPDATE_STATUSES, "completed"].map(() => "?").join(",")})
|
||||
ORDER BY created_at DESC LIMIT 1
|
||||
`).get(request.auth!.admin.id, ...ACTIVE_UPDATE_STATUSES, "completed") as Record<string, unknown> | undefined;
|
||||
return {
|
||||
...cached,
|
||||
strategy: config.updateStrategy,
|
||||
|
||||
+22
-2
@@ -1,5 +1,5 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { lstat, mkdir, mkdtemp, readFile, realpath, rm } from "node:fs/promises";
|
||||
import { cp, lstat, mkdir, mkdtemp, readFile, realpath, rm } from "node:fs/promises";
|
||||
import path from "node:path";
|
||||
import { pathToFileURL } from "node:url";
|
||||
import type Database from "better-sqlite3";
|
||||
@@ -10,6 +10,7 @@ import { writeAudit } from "../audit.js";
|
||||
import {
|
||||
atomicSwitchDirectory,
|
||||
atomicSwitchRelease,
|
||||
applicationUpdateRuntimeHash,
|
||||
compareSemver,
|
||||
createSafeArchive,
|
||||
detectPlatform,
|
||||
@@ -19,6 +20,7 @@ import {
|
||||
isNewerVersion,
|
||||
normalizeReleasePermissions,
|
||||
parseSemver,
|
||||
runtimeHashFromLockfile,
|
||||
selectReleaseAsset,
|
||||
sanitizeAssetName,
|
||||
validateHttpsUrl,
|
||||
@@ -212,9 +214,16 @@ async function resolveRelease(options: UpdateRunOptions, platform: ReturnType<ty
|
||||
if (options.metadataUrl) {
|
||||
const metadataUrl = validateHttpsUrl(options.metadataUrl, options);
|
||||
const release = await fetchReleaseMetadata(metadataUrl, options);
|
||||
let runtimeHash: string | undefined;
|
||||
try {
|
||||
runtimeHash = runtimeHashFromLockfile(await readFile(path.join(options.currentDir, "pnpm-lock.yaml")));
|
||||
} catch {
|
||||
// Fall back to the full archive when the current installation predates
|
||||
// runtime fingerprints or is missing deployment provenance.
|
||||
}
|
||||
let asset = options.assetUrl && !options.requireSignature
|
||||
? { name: sanitizeAssetName(options.assetName ?? path.basename(new URL(options.assetUrl).pathname)), url: validateHttpsUrl(options.assetUrl, { ...options, baseUrl: metadataUrl }).toString(), ...(options.expectedSha256 ? { sha256: options.expectedSha256 } : {}) }
|
||||
: selectReleaseAsset(release, platform);
|
||||
: selectReleaseAsset(release, platform, runtimeHash);
|
||||
if (!asset) throw new Error("没有匹配当前平台的更新文件");
|
||||
const integrity = await attachSidecarHash(release, asset, {
|
||||
allowedHosts: options.allowedHosts ?? [],
|
||||
@@ -314,6 +323,17 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
|
||||
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
|
||||
const stagedDir = path.join(workspace, "payload");
|
||||
await extractSafeArchive(archivePath, stagedDir, options.maxBytes === undefined ? {} : { maxBytes: options.maxBytes });
|
||||
if (applicationUpdateRuntimeHash(resolved.asset.name)) {
|
||||
const currentRelease = await realpath(options.currentDir).catch(() => { throw new Error("当前安装目录无效"); });
|
||||
const currentInfo = await lstat(currentRelease).catch(() => null);
|
||||
if (!currentInfo?.isDirectory() || currentInfo.isSymbolicLink()) throw new Error("当前安装目录无效");
|
||||
for (const entry of ["node_modules", "runtime", "pnpm-lock.yaml"] as const) {
|
||||
const source = path.join(currentRelease, entry);
|
||||
const sourceInfo = await lstat(source).catch(() => null);
|
||||
if (!sourceInfo || sourceInfo.isSymbolicLink()) throw new Error("当前运行时不完整,无法应用轻量更新");
|
||||
await cp(source, path.join(stagedDir, entry), { recursive: sourceInfo.isDirectory(), errorOnExist: true, force: false });
|
||||
}
|
||||
}
|
||||
await normalizeReleasePermissions(stagedDir);
|
||||
const payloadInfo = await lstat(path.join(stagedDir, "dist")).catch(() => null);
|
||||
if (!payloadInfo?.isDirectory() || payloadInfo.isSymbolicLink()) throw new Error("发布包缺少 dist 目录");
|
||||
|
||||
@@ -43,21 +43,6 @@ function csvEnv(name: string): string[] {
|
||||
.filter(Boolean);
|
||||
}
|
||||
|
||||
function originListEnv(name: string, primary: string): string[] {
|
||||
const values = [primary, ...csvEnv(name)];
|
||||
const origins = new Set<string>();
|
||||
for (const value of values) {
|
||||
try {
|
||||
const parsed = new URL(value);
|
||||
if (!["http:", "https:"].includes(parsed.protocol) || parsed.username || parsed.password || parsed.pathname !== "/" && parsed.pathname !== "" || parsed.search || parsed.hash) throw new Error();
|
||||
origins.add(parsed.origin);
|
||||
} catch {
|
||||
throw new Error(`${name} 必须是逗号分隔的 HTTP(S) Origin(不含路径)`);
|
||||
}
|
||||
}
|
||||
return [...origins];
|
||||
}
|
||||
|
||||
function updatePublicKeyEnv(): string | undefined {
|
||||
const inline = process.env.TALLYNOTE_UPDATE_PUBLIC_KEY?.trim();
|
||||
const file = process.env.TALLYNOTE_UPDATE_PUBLIC_KEY_FILE?.trim();
|
||||
@@ -113,7 +98,6 @@ export function loadConfig() {
|
||||
throw new Error("TALLYNOTE_PUBLIC_ORIGIN 不能使用通配监听地址,请填写服务器 IP 或域名");
|
||||
}
|
||||
const localOrigin = ["127.0.0.1", "localhost", "::1"].includes(publicHost);
|
||||
const allowedOrigins = originListEnv("TALLYNOTE_ALLOWED_ORIGINS", parsedOrigin.origin);
|
||||
const appVersion = (() => {
|
||||
try {
|
||||
const packageJson = JSON.parse(readFileSync(path.join(projectRoot, "package.json"), "utf8")) as { version?: unknown };
|
||||
@@ -143,7 +127,6 @@ export function loadConfig() {
|
||||
host,
|
||||
port,
|
||||
publicOrigin: parsedOrigin.origin,
|
||||
allowedOrigins,
|
||||
timezone,
|
||||
trustProxy: trustProxyEnv(),
|
||||
cookieSecure,
|
||||
|
||||
@@ -13,6 +13,7 @@ import {
|
||||
fetchReleaseText,
|
||||
isNewerVersion,
|
||||
parseSemver,
|
||||
runtimeHashFromLockfile,
|
||||
sanitizeAssetName,
|
||||
selectReleaseAsset,
|
||||
validateHttpsUrl,
|
||||
@@ -204,7 +205,14 @@ export async function checkForUpdate(database: Database.Database, config: AppCon
|
||||
} catch {
|
||||
throw new AppError(502, "UPDATE_CHECK_FAILED", "暂时无法获取最新版本,请稍后重试");
|
||||
}
|
||||
let asset = selectReleaseAsset(metadata, platform);
|
||||
let runtimeHash: string | undefined;
|
||||
try {
|
||||
runtimeHash = runtimeHashFromLockfile(readFileSync(path.join(config.projectRoot, "pnpm-lock.yaml")));
|
||||
} catch {
|
||||
// Legacy or source installations may not contain the lockfile. They stay
|
||||
// on the full release asset instead of risking an incompatible runtime.
|
||||
}
|
||||
let asset = selectReleaseAsset(metadata, platform, runtimeHash);
|
||||
let signatureVerified = false;
|
||||
if (asset) {
|
||||
const integrity = await attachSidecarHash(metadata, asset, {
|
||||
|
||||
+20
-2
@@ -43,6 +43,16 @@ export type ReleaseMetadata = {
|
||||
assets: ReleaseAsset[];
|
||||
};
|
||||
|
||||
const APPLICATION_UPDATE_ASSET = /\.update-([a-f0-9]{64})\.tar\.gz$/i;
|
||||
|
||||
export function applicationUpdateRuntimeHash(assetName: string): string | undefined {
|
||||
return APPLICATION_UPDATE_ASSET.exec(assetName)?.[1]?.toLowerCase();
|
||||
}
|
||||
|
||||
export function runtimeHashFromLockfile(lockfile: string | Buffer): string {
|
||||
return createHash("sha256").update(lockfile).digest("hex");
|
||||
}
|
||||
|
||||
export type UrlPolicy = {
|
||||
/** Host names or HTTPS URLs which are allowed for requests. */
|
||||
allowedHosts?: readonly string[] | undefined;
|
||||
@@ -379,7 +389,7 @@ export async function fetchReleaseBytes(
|
||||
}
|
||||
}
|
||||
|
||||
export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPlatform()): ReleaseAsset | undefined {
|
||||
export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPlatform(), runtimeHash?: string): ReleaseAsset | undefined {
|
||||
const platformCandidates = release.assets.filter((asset) => {
|
||||
const name = asset.name.toLowerCase();
|
||||
return platform.aliases.filter((alias) => alias.toLowerCase().includes(platform.arch.toLowerCase())).some((alias) => name.includes(alias.toLowerCase()));
|
||||
@@ -398,7 +408,15 @@ export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPl
|
||||
const target = platform.target.toLowerCase();
|
||||
return Number(b.name.toLowerCase().includes(target)) - Number(a.name.toLowerCase().includes(target));
|
||||
});
|
||||
return candidates[0];
|
||||
const normalizedRuntimeHash = runtimeHash?.trim().toLowerCase();
|
||||
if (normalizedRuntimeHash && /^[a-f0-9]{64}$/.test(normalizedRuntimeHash)) {
|
||||
const applicationUpdate = candidates.find((asset) => applicationUpdateRuntimeHash(asset.name) === normalizedRuntimeHash);
|
||||
if (applicationUpdate) return applicationUpdate;
|
||||
}
|
||||
// Older clients choose the first matching asset. Releases therefore keep
|
||||
// the traditional full archive first, while current clients explicitly
|
||||
// opt into a compatible application-only asset.
|
||||
return candidates.find((asset) => !applicationUpdateRuntimeHash(asset.name));
|
||||
}
|
||||
|
||||
export function sanitizeAssetName(value: string): string {
|
||||
|
||||
@@ -3,7 +3,6 @@ TALLYNOTE_PORT=3000
|
||||
TALLYNOTE_DATA_DIR=/var/lib/tallynote
|
||||
TALLYNOTE_INSTALL_PREFIX=/opt/tallynote
|
||||
TALLYNOTE_PUBLIC_ORIGIN=http://127.0.0.1:3000
|
||||
TALLYNOTE_ALLOWED_ORIGINS=http://127.0.0.1:3000
|
||||
TALLYNOTE_COOKIE_SECURE=false
|
||||
TALLYNOTE_ALLOW_INSECURE_HTTP=false
|
||||
TALLYNOTE_TIMEZONE=Asia/Shanghai
|
||||
|
||||
+3
-3
@@ -129,10 +129,10 @@ describe("TallyNote API", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("拒绝没有 Origin 的写请求", async () => {
|
||||
it("反向代理缺少 Origin 时仍允许登录请求进入认证流程", async () => {
|
||||
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
|
||||
expect(response.statusCode).toBe(403);
|
||||
expect(response.json().error.code).toBe("ORIGIN_FORBIDDEN");
|
||||
expect(response.statusCode).toBe(401);
|
||||
expect(response.json().error.code).toBe("INVALID_CREDENTIALS");
|
||||
});
|
||||
|
||||
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
|
||||
|
||||
@@ -5,7 +5,7 @@ import { tmpdir } from "node:os";
|
||||
import path from "node:path";
|
||||
import { loadConfig, prepareDataDirectories } from "../server/config.js";
|
||||
|
||||
const keys = ["TALLYNOTE_DATA_DIR", "TALLYNOTE_HOST", "TALLYNOTE_PORT", "TALLYNOTE_PUBLIC_ORIGIN", "TALLYNOTE_ALLOWED_ORIGINS", "TALLYNOTE_COOKIE_SECURE", "TALLYNOTE_ALLOW_INSECURE_HTTP", "TALLYNOTE_TRUST_PROXY", "NODE_ENV", "TALLYNOTE_ENV", "TALLYNOTE_UPDATE_STRATEGY", "TALLYNOTE_UPDATE_ALLOWED_HOSTS", "TALLYNOTE_UPDATE_REQUIRE_SIGNATURE", "TALLYNOTE_UPDATE_PUBLIC_KEY", "TALLYNOTE_UPDATE_PUBLIC_KEY_FILE"];
|
||||
const keys = ["TALLYNOTE_DATA_DIR", "TALLYNOTE_HOST", "TALLYNOTE_PORT", "TALLYNOTE_PUBLIC_ORIGIN", "TALLYNOTE_COOKIE_SECURE", "TALLYNOTE_ALLOW_INSECURE_HTTP", "TALLYNOTE_TRUST_PROXY", "NODE_ENV", "TALLYNOTE_ENV", "TALLYNOTE_UPDATE_STRATEGY", "TALLYNOTE_UPDATE_ALLOWED_HOSTS", "TALLYNOTE_UPDATE_REQUIRE_SIGNATURE", "TALLYNOTE_UPDATE_PUBLIC_KEY", "TALLYNOTE_UPDATE_PUBLIC_KEY_FILE"];
|
||||
|
||||
afterEach(() => { for (const key of keys) delete process.env[key]; });
|
||||
|
||||
@@ -48,14 +48,6 @@ describe("部署安全配置", () => {
|
||||
expect(loadConfig().trustProxy).toBe(1);
|
||||
});
|
||||
|
||||
it("允许显式列出反向代理的多个可信 Origin", () => {
|
||||
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://tally.example.test";
|
||||
process.env.TALLYNOTE_COOKIE_SECURE = "true";
|
||||
process.env.TALLYNOTE_ALLOWED_ORIGINS = "https://tally.example.test, https://tally.internal.test:8443";
|
||||
expect(loadConfig().allowedOrigins).toEqual(["https://tally.example.test", "https://tally.internal.test:8443"]);
|
||||
process.env.TALLYNOTE_ALLOWED_ORIGINS = "https://tally.example.test/app";
|
||||
expect(() => loadConfig()).toThrow(/Origin/);
|
||||
});
|
||||
|
||||
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
|
||||
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||
|
||||
@@ -137,6 +137,24 @@ describe("更新 API", () => {
|
||||
expect(disabledConfig.updateStrategy).toBe("disabled");
|
||||
});
|
||||
|
||||
it("首次进入状态页不会展示历史失败任务,也不会阻断新的检查", async () => {
|
||||
const session = await login("update-history");
|
||||
const admin = database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-history") as { id: string };
|
||||
const now = Date.now();
|
||||
database.sqlite.prepare(`
|
||||
INSERT INTO update_jobs(id, admin_id, operation, status, version, platform, asset_url, error_message, created_at, updated_at)
|
||||
VALUES (?, ?, 'download', 'failed', '1.1.0', ?, 'https://updates.example/old.tar.gz', 'old failure', ?, ?)
|
||||
`).run(randomUUID(), admin.id, detectPlatform().target, now - 60_000, now - 60_000);
|
||||
const initial = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
|
||||
expect(initial.statusCode).toBe(200);
|
||||
expect(initial.json().job).toBeNull();
|
||||
|
||||
mockRelease();
|
||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||
expect(checked.statusCode).toBe(200);
|
||||
expect(checked.json().latest).toMatchObject({ version: "1.2.0", isNewer: true });
|
||||
});
|
||||
|
||||
it("更新任务只对发起管理员可见,并隐藏内部错误详情", async () => {
|
||||
const owner = await login("update-owner");
|
||||
const other = await login("update-other");
|
||||
|
||||
@@ -6,6 +6,7 @@ import path from "node:path";
|
||||
import { createHash, generateKeyPairSync, randomUUID, sign } from "node:crypto";
|
||||
import {
|
||||
atomicSwitchRelease,
|
||||
applicationUpdateRuntimeHash,
|
||||
createSafeArchive,
|
||||
detectPlatform,
|
||||
downloadReleaseAsset,
|
||||
@@ -16,6 +17,7 @@ import {
|
||||
normalizeReleasePermissions,
|
||||
sanitizeAssetName,
|
||||
selectReleaseAsset,
|
||||
runtimeHashFromLockfile,
|
||||
validateHttpsUrl,
|
||||
} from "../server/update.js";
|
||||
import { finalizeUpdateJob, runUpdate } from "../server/cli/update.js";
|
||||
@@ -50,6 +52,17 @@ describe("更新安全工具", () => {
|
||||
expect(() => sanitizeAssetName("../release.tar.gz")).toThrow();
|
||||
});
|
||||
|
||||
it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => {
|
||||
const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n");
|
||||
const full = { name: "tallynote-1.2.0-linux-x64-glibc.tar.gz", url: "https://updates.example/full" };
|
||||
const app = { name: `tallynote-1.2.0-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" };
|
||||
const release = { version: "1.2.0", assets: [full, app] };
|
||||
expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash);
|
||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app);
|
||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full);
|
||||
expect(applicationUpdateRuntimeHash(full.name)).toBeUndefined();
|
||||
});
|
||||
|
||||
it("验证 SHA256SUMS 的 Ed25519 detached signature", () => {
|
||||
const { publicKey, privateKey } = generateKeyPairSync("ed25519");
|
||||
const payload = "a".repeat(64) + " tallynote.tar.gz\n";
|
||||
|
||||
@@ -66,7 +66,7 @@ export default function ExpenseDetail({ expense, timezone = "Asia/Shanghai", onC
|
||||
</Drawer>
|
||||
<Dialog visible={action === "status"} header={detail.status === "reimbursed" ? "改回未报销?" : "标记为已报销?"} confirmBtn={{ content: "确认变更", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void updateStatus()} onCancel={() => { if (!busy) setAction(null); }}>{detail.status === "reimbursed" ? "这笔账目会重新出现在未报销列表。" : "确认这笔账目已完成报销,并从未报销列表移出?"}</Dialog>
|
||||
<Dialog visible={action === "trash"} header="移入回收站?" confirmBtn={{ content: "移入回收站", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void trash()} onCancel={() => { if (!busy) setAction(null); }}>账目会从普通列表和导出结果中隐藏,附件会保留,可在回收站恢复。</Dialog>
|
||||
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert"><AlertCircle size={16} />{removeError}</div>}</>}</Dialog>
|
||||
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert">{removeError}</div>}</>}</Dialog>
|
||||
<Dialog visible={Boolean(preview)} header={preview?.originalName} onClose={() => setPreview(null)} cancelBtn="关闭" footer={null}>{preview && <div className="tn-preview">{preview.mimeType.startsWith("image/") ? <img src={`/api/attachments/${preview.id}/content`} alt={preview.originalName} /> : <iframe src={`/api/attachments/${preview.id}/content`} title={preview.originalName} />}</div>}</Dialog>
|
||||
</>;
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,283 @@
|
||||
export type MockScenario =
|
||||
| "latest" // 已是最新
|
||||
| "available" // 发现新版本(待下载)
|
||||
| "downloading_30" // 下载中 30%
|
||||
| "downloading_85" // 下载中 85% + 高速
|
||||
| "staged" // 下载完成已校验,待立即更新
|
||||
| "backing_up" // 正在备份数据
|
||||
| "applying" // 正在原子切换并重启中(倒计时)
|
||||
| "completed" // 更新完成
|
||||
| "failed_verify" // 完整性校验失败
|
||||
| "disabled"; // 手动模式未配置源
|
||||
|
||||
export interface MockUpdateState {
|
||||
info: any;
|
||||
title: string;
|
||||
description: string;
|
||||
}
|
||||
|
||||
export const MOCK_SCENARIOS: Record<MockScenario, MockUpdateState> = {
|
||||
latest: {
|
||||
title: "版本健康(已是最新)",
|
||||
description: "展示当前运行版本已是最新,各项指标正常,无待处理任务",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 600_000,
|
||||
latest: {
|
||||
version: "1.1.22",
|
||||
tagName: "v1.1.22",
|
||||
releaseName: "v1.1.22 稳定版",
|
||||
publishedAt: new Date(Date.now() - 3600_000 * 24).toISOString(),
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: false,
|
||||
assetName: "tallynote-1.1.22-linux-x64-glibc.tar.gz",
|
||||
assetSize: 120540160,
|
||||
notes: "### TallyNote 1.1.22\n\n- 优化反向代理下登录兼容性\n- 增强安全审计与防重放机制\n- 前端组件性能深度优化",
|
||||
},
|
||||
job: null,
|
||||
},
|
||||
},
|
||||
available: {
|
||||
title: "发现新版本(待下载)",
|
||||
description: "检查到官方发布了更高版本,显示更新日志与文件校验信息,可点击下载",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 60_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
releaseName: "v1.1.23 重大更新",
|
||||
publishedAt: new Date(Date.now() - 1800_000).toISOString(),
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
notes: "### TallyNote 1.1.23\n\n- 【新功能】系统更新中心全面重构,支持动态速率流光进度条与平滑重启倒计时\n- 【交互】优化抽屉展开动效与手机端自适应导航\n- 【安全】发布包支持双重 Ed25519 签名与 SHA-256 清单交叉校验",
|
||||
},
|
||||
job: null,
|
||||
},
|
||||
},
|
||||
downloading_30: {
|
||||
title: "下载更新中(进度 38%)",
|
||||
description: "展示真实下载速率、已下载字节数与动态流光进度条",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-001",
|
||||
operation: "download",
|
||||
status: "downloading",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
sizeBytes: 121000000,
|
||||
downloadedBytes: 46200000,
|
||||
downloadStartedAt: Date.now() - 10000,
|
||||
downloadSpeedBps: 8800000, // 8.4 MB/s
|
||||
createdAt: Date.now() - 10000,
|
||||
updatedAt: Date.now(),
|
||||
},
|
||||
},
|
||||
},
|
||||
downloading_85: {
|
||||
title: "下载冲刺中(进度 88%)",
|
||||
description: "高速冲刺状态,即将触发 SHA-256 校验",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-002",
|
||||
operation: "download",
|
||||
status: "downloading",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
sizeBytes: 121000000,
|
||||
downloadedBytes: 106480000,
|
||||
downloadStartedAt: Date.now() - 15000,
|
||||
downloadSpeedBps: 12500000, // 11.9 MB/s
|
||||
createdAt: Date.now() - 15000,
|
||||
updatedAt: Date.now(),
|
||||
},
|
||||
},
|
||||
},
|
||||
staged: {
|
||||
title: "下载完成(待立即应用)",
|
||||
description: "更新包与签名均已校验就绪,随时可以安全点击【立即更新】",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
notes: "### TallyNote 1.1.23\n\n- 更新包已完整解压检验通过,具备升级条件。",
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-003",
|
||||
operation: "download",
|
||||
status: "staged",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
sizeBytes: 121000000,
|
||||
downloadedBytes: 121000000,
|
||||
createdAt: Date.now() - 60000,
|
||||
updatedAt: Date.now() - 5000,
|
||||
},
|
||||
},
|
||||
},
|
||||
backing_up: {
|
||||
title: "数据备份中(更新保护)",
|
||||
description: "正在为 /var/lib/tallynote 生成自动还原快照",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
|
||||
job: {
|
||||
id: "mock-job-004",
|
||||
operation: "apply",
|
||||
status: "backing_up",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
createdAt: Date.now() - 20000,
|
||||
updatedAt: Date.now() - 2000,
|
||||
},
|
||||
},
|
||||
},
|
||||
applying: {
|
||||
title: "服务平滑重启中(倒计时中)",
|
||||
description: "已原子切换版本,systemd 正在热重启,前端实时探活",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
|
||||
job: {
|
||||
id: "mock-job-005",
|
||||
operation: "apply",
|
||||
status: "applying",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
applyQueuedAt: Date.now() - 12000,
|
||||
restartWindowSeconds: 30,
|
||||
restartDeadline: Date.now() + 18000,
|
||||
createdAt: Date.now() - 25000,
|
||||
updatedAt: Date.now() - 2000,
|
||||
},
|
||||
},
|
||||
},
|
||||
completed: {
|
||||
title: "更新成功完成",
|
||||
description: "新版本健康检查通过,已平滑无感升级至最新",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.23",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 30_000,
|
||||
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: false },
|
||||
job: {
|
||||
id: "mock-job-006",
|
||||
operation: "apply",
|
||||
status: "completed",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
completedAt: Date.now() - 10000,
|
||||
createdAt: Date.now() - 45000,
|
||||
updatedAt: Date.now() - 10000,
|
||||
},
|
||||
},
|
||||
},
|
||||
failed_verify: {
|
||||
title: "更新失败状态(安全拦截)",
|
||||
description: "模拟签名不匹配或发布包篡改时的安全拦截展示与错误提示",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: false,
|
||||
signatureReady: false,
|
||||
isNewer: true,
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-007",
|
||||
operation: "download",
|
||||
status: "failed",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
errorMessage: "发布包 SHA-256 校验与清单不一致,系统已自动阻断并保护原有数据。",
|
||||
createdAt: Date.now() - 30000,
|
||||
updatedAt: Date.now() - 5000,
|
||||
},
|
||||
},
|
||||
},
|
||||
disabled: {
|
||||
title: "手动源码模式",
|
||||
description: "未接入 systemd 时的只读说明与命令引导展示",
|
||||
info: {
|
||||
configured: false,
|
||||
strategy: "disabled",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "macOS/darwin", os: "darwin", arch: "arm64" },
|
||||
checkedAt: Date.now() - 3600_000,
|
||||
latest: null,
|
||||
job: null,
|
||||
},
|
||||
},
|
||||
};
|
||||
@@ -410,6 +410,34 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
||||
@keyframes tn-app-enter { from { opacity: 0; } to { opacity: 1; } }
|
||||
@keyframes tn-auth-page-in { from { opacity: 0; transform: translateY(4px); } to { opacity: 1; transform: translateY(0); } }
|
||||
.t-dialog { border: 1px solid var(--tn-border); border-radius: 4px; box-shadow: 0 18px 42px rgba(8, 47, 118, .18); }
|
||||
/* TDesign Dialog global no-icon & pure baseline typography normalization */
|
||||
.t-dialog__header .t-icon:not(.t-icon-close),
|
||||
.t-dialog__body .t-icon,
|
||||
.t-dialog .t-icon.t-is-info,
|
||||
.t-dialog .t-icon.t-is-success,
|
||||
.t-dialog .t-icon.t-is-warning,
|
||||
.t-dialog .t-icon.t-is-error {
|
||||
display: none !important;
|
||||
}
|
||||
.t-dialog__header {
|
||||
font-size: 16px;
|
||||
font-weight: 600;
|
||||
color: var(--tn-navy-900);
|
||||
line-height: 1.4;
|
||||
margin-bottom: 8px;
|
||||
gap: 0 !important;
|
||||
}
|
||||
.t-dialog__header-content {
|
||||
display: block !important;
|
||||
width: 100%;
|
||||
}
|
||||
.t-dialog__body {
|
||||
font-size: 13.5px;
|
||||
line-height: 1.65;
|
||||
color: var(--tn-text);
|
||||
padding: 8px 0 20px 0;
|
||||
}
|
||||
|
||||
.t-dialog__mask { background: var(--td-mask-active) !important; }
|
||||
.t-dialog__footer .t-button { min-width: 76px; }
|
||||
@media (max-width: 900px) {
|
||||
@@ -537,3 +565,545 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
||||
@media (prefers-reduced-motion: reduce) {
|
||||
*, *::before, *::after { animation-duration: .01ms !important; animation-iteration-count: 1 !important; transition-duration: .01ms !important; scroll-behavior: auto !important; }
|
||||
}
|
||||
|
||||
/* ==========================================================================
|
||||
TallyNote Update Center (Redesigned UI & Interactive Styles)
|
||||
========================================================================== */
|
||||
|
||||
/* Mock Console Controller */
|
||||
.tn-mock-console {
|
||||
margin-bottom: 16px;
|
||||
padding: 14px 18px;
|
||||
background: #f8fbff;
|
||||
border: 1px dashed var(--td-brand-color-3);
|
||||
border-radius: 4px;
|
||||
}
|
||||
.tn-mock-console-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
flex-wrap: wrap;
|
||||
gap: 8px;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-mock-console-title {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
font-size: 13px;
|
||||
color: var(--tn-navy-900);
|
||||
}
|
||||
.tn-mock-console-tip {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-mock-scenario-chips {
|
||||
display: flex;
|
||||
flex-wrap: wrap;
|
||||
gap: 8px;
|
||||
}
|
||||
.tn-scenario-chip {
|
||||
padding: 5px 11px;
|
||||
font-size: 12px;
|
||||
border: 1px solid var(--tn-border);
|
||||
border-radius: 3px;
|
||||
background: #ffffff;
|
||||
color: var(--tn-text-secondary);
|
||||
cursor: pointer;
|
||||
transition: all 0.16s ease;
|
||||
}
|
||||
.tn-scenario-chip:hover {
|
||||
border-color: var(--td-brand-color-4);
|
||||
color: var(--td-brand-color);
|
||||
background: var(--td-brand-color-1);
|
||||
}
|
||||
.tn-scenario-chip.active {
|
||||
background: var(--td-brand-color);
|
||||
border-color: var(--td-brand-color);
|
||||
color: #ffffff;
|
||||
font-weight: 600;
|
||||
box-shadow: 0 2px 6px rgba(23, 92, 211, 0.2);
|
||||
}
|
||||
|
||||
/* Update Page Actions */
|
||||
.tn-update-page-actions {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 10px;
|
||||
}
|
||||
|
||||
/* 4 Metrics Grid */
|
||||
.tn-update-metrics-grid {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(4, minmax(0, 1fr));
|
||||
gap: 14px;
|
||||
margin-bottom: 16px;
|
||||
}
|
||||
.tn-metric-card .t-card__body {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
justify-content: space-between;
|
||||
padding: 16px 18px;
|
||||
min-height: 104px;
|
||||
}
|
||||
.tn-metric-content {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-metric-label {
|
||||
display: block;
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
margin-bottom: 4px;
|
||||
}
|
||||
.tn-metric-value {
|
||||
font-size: 20px;
|
||||
font-weight: 700;
|
||||
color: var(--tn-navy-900);
|
||||
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||
font-variant-numeric: tabular-nums;
|
||||
line-height: 1.2;
|
||||
}
|
||||
.tn-metric-foot {
|
||||
margin-top: 6px;
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-muted);
|
||||
}
|
||||
|
||||
/* Stepper Surface */
|
||||
.tn-stepper-surface {
|
||||
margin-bottom: 16px;
|
||||
padding: 20px;
|
||||
}
|
||||
.tn-stepper-head {
|
||||
display: flex;
|
||||
align-items: flex-start;
|
||||
justify-content: space-between;
|
||||
gap: 16px;
|
||||
margin-bottom: 20px;
|
||||
}
|
||||
.tn-section-heading {
|
||||
margin: 0 0 4px;
|
||||
font-size: 15px;
|
||||
font-weight: 700;
|
||||
color: var(--tn-text);
|
||||
}
|
||||
.tn-section-subheading {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-stepper-wrap {
|
||||
padding: 10px 0 20px;
|
||||
}
|
||||
.tn-stepper-wrap .t-steps {
|
||||
max-width: 860px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
.tn-stepper-wrap {
|
||||
min-width: 0;
|
||||
overflow-x: auto;
|
||||
scrollbar-width: thin;
|
||||
scrollbar-color: var(--td-brand-color-3) transparent;
|
||||
}
|
||||
.tn-stepper-wrap .t-steps {
|
||||
min-width: 680px;
|
||||
}
|
||||
|
||||
/* Job Runtime Panel (Active download & progress) */
|
||||
.tn-job-runtime-panel {
|
||||
margin-top: 14px;
|
||||
padding: 16px;
|
||||
background: #f8fbff;
|
||||
border: 1px solid var(--td-brand-color-2);
|
||||
border-radius: 4px;
|
||||
}
|
||||
.tn-job-runtime-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
flex-wrap: wrap;
|
||||
gap: 10px;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-job-status-badge {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
font-size: 13px;
|
||||
color: var(--tn-navy-900);
|
||||
min-width: 0;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
.tn-pulse-dot {
|
||||
width: 8px;
|
||||
height: 8px;
|
||||
border-radius: 50%;
|
||||
background: var(--td-brand-color);
|
||||
box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7);
|
||||
animation: tn-pulse 1.8s infinite;
|
||||
}
|
||||
@keyframes tn-pulse {
|
||||
0% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7); }
|
||||
70% { transform: scale(1); box-shadow: 0 0 0 6px rgba(23, 92, 211, 0); }
|
||||
100% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0); }
|
||||
}
|
||||
.tn-job-subtext {
|
||||
color: var(--tn-text-secondary);
|
||||
font-size: 12px;
|
||||
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
.tn-speed-indicator {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
min-width: 0;
|
||||
flex-wrap: wrap;
|
||||
}
|
||||
.tn-speed-badge {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 4px;
|
||||
padding: 2px 8px;
|
||||
border-radius: 3px;
|
||||
background: #ffffff;
|
||||
border: 1px solid var(--td-brand-color-3);
|
||||
color: var(--td-brand-color);
|
||||
font-size: 12px;
|
||||
font-weight: 600;
|
||||
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
.tn-eta-badge {
|
||||
display: inline-block;
|
||||
padding: 2px 8px;
|
||||
border-radius: 3px;
|
||||
background: #f2f5f9;
|
||||
color: var(--tn-text-secondary);
|
||||
font-size: 12px;
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
|
||||
/* Progress Bar with modern stream light effect */
|
||||
.tn-progress-stream {
|
||||
position: relative;
|
||||
height: 8px;
|
||||
background: #e1e9f4;
|
||||
border-radius: 999px;
|
||||
overflow: hidden;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-progress-stream-bar {
|
||||
height: 100%;
|
||||
background: linear-gradient(90deg, #175cd3 0%, #3d7be5 100%);
|
||||
border-radius: inherit;
|
||||
transition: width 0.35s ease;
|
||||
position: relative;
|
||||
}
|
||||
.tn-progress-stream-bar::after {
|
||||
content: "";
|
||||
position: absolute;
|
||||
top: 0; left: 0; bottom: 0; right: 0;
|
||||
background-image: linear-gradient(
|
||||
-45deg,
|
||||
rgba(255, 255, 255, 0.25) 25%,
|
||||
transparent 25%,
|
||||
transparent 50%,
|
||||
rgba(255, 255, 255, 0.25) 50%,
|
||||
rgba(255, 255, 255, 0.25) 75%,
|
||||
transparent 75%,
|
||||
transparent
|
||||
);
|
||||
background-size: 30px 30px;
|
||||
animation: tn-stream-flow 1.5s linear infinite;
|
||||
}
|
||||
@keyframes tn-stream-flow {
|
||||
0% { background-position: 0 0; }
|
||||
100% { background-position: 30px 30px; }
|
||||
}
|
||||
|
||||
.tn-job-runtime-desc {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
/* Restarting State Banner */
|
||||
.tn-restarting-banner {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 12px;
|
||||
padding: 8px 12px;
|
||||
background: #fff8e6;
|
||||
border: 1px solid #ffd666;
|
||||
border-radius: 3px;
|
||||
color: #8c5b00;
|
||||
}
|
||||
.tn-restarting-spinner {
|
||||
color: #faad14;
|
||||
}
|
||||
|
||||
/* Release Surface */
|
||||
.tn-release-surface {
|
||||
margin-bottom: 16px;
|
||||
padding: 20px;
|
||||
}
|
||||
.tn-release-notes-surface {
|
||||
margin-bottom: 16px;
|
||||
padding: 20px;
|
||||
}
|
||||
.tn-release-notes-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
gap: 16px;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-release-header {
|
||||
display: flex;
|
||||
align-items: flex-start;
|
||||
justify-content: space-between;
|
||||
gap: 16px;
|
||||
}
|
||||
.tn-release-tag-row {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
margin-bottom: 6px;
|
||||
}
|
||||
.tn-release-title {
|
||||
margin: 0 0 6px;
|
||||
font-size: 22px;
|
||||
font-weight: 700;
|
||||
color: var(--tn-navy-900);
|
||||
}
|
||||
.tn-release-time {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-release-notes-box {
|
||||
margin: 0;
|
||||
padding: 12px 16px;
|
||||
background: #f8fafc;
|
||||
border: 1px solid var(--tn-border);
|
||||
border-left: 3px solid var(--td-brand-color);
|
||||
border-radius: 3px;
|
||||
}
|
||||
.tn-release-notes-heading {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 6px;
|
||||
font-size: 12px;
|
||||
font-weight: 600;
|
||||
color: var(--tn-navy-900);
|
||||
margin-bottom: 6px;
|
||||
}
|
||||
.tn-release-notes-content {
|
||||
font-size: 13px;
|
||||
color: var(--tn-text-secondary);
|
||||
line-height: 1.6;
|
||||
max-height: 140px;
|
||||
overflow-y: auto;
|
||||
}
|
||||
|
||||
.tn-markdown-notes {
|
||||
color: inherit;
|
||||
line-height: 1.7;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
.tn-markdown-notes p,
|
||||
.tn-markdown-notes h3,
|
||||
.tn-markdown-notes h4,
|
||||
.tn-markdown-notes h5 {
|
||||
margin: 0 0 8px;
|
||||
}
|
||||
.tn-markdown-notes p:last-child,
|
||||
.tn-markdown-notes ul:last-child,
|
||||
.tn-markdown-notes pre:last-child,
|
||||
.tn-markdown-notes h3:last-child,
|
||||
.tn-markdown-notes h4:last-child,
|
||||
.tn-markdown-notes h5:last-child {
|
||||
margin-bottom: 0;
|
||||
}
|
||||
.tn-markdown-notes h3,
|
||||
.tn-markdown-notes h4,
|
||||
.tn-markdown-notes h5 {
|
||||
color: var(--tn-navy-900);
|
||||
font-weight: 700;
|
||||
}
|
||||
.tn-markdown-notes h3 { font-size: 15px; }
|
||||
.tn-markdown-notes h4 { font-size: 14px; }
|
||||
.tn-markdown-notes h5 { font-size: 13px; }
|
||||
.tn-markdown-notes ul {
|
||||
margin: 0 0 8px;
|
||||
padding-left: 20px;
|
||||
}
|
||||
.tn-markdown-notes li { margin: 3px 0; }
|
||||
.tn-markdown-notes strong { color: var(--tn-navy-900); font-weight: 700; }
|
||||
.tn-markdown-notes code {
|
||||
padding: 1px 4px;
|
||||
border: 1px solid var(--tn-border-subtle);
|
||||
border-radius: 3px;
|
||||
background: #f2f5f9;
|
||||
color: var(--tn-navy-900);
|
||||
font-family: "Plus Jakarta Sans Variable", ui-monospace, monospace;
|
||||
font-size: .92em;
|
||||
}
|
||||
.tn-markdown-notes pre {
|
||||
margin: 0 0 8px;
|
||||
padding: 10px 12px;
|
||||
overflow-x: auto;
|
||||
border: 1px solid var(--tn-border-subtle);
|
||||
border-radius: 3px;
|
||||
background: #f8fafc;
|
||||
white-space: pre-wrap;
|
||||
}
|
||||
.tn-markdown-notes pre code { padding: 0; border: 0; background: transparent; }
|
||||
.tn-markdown-notes a { color: var(--td-brand-color); text-decoration: underline; text-underline-offset: 2px; }
|
||||
.tn-markdown-notes-compact { font-size: 13px; }
|
||||
|
||||
/* Facts Grid */
|
||||
.tn-facts-grid {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(3, minmax(0, 1fr));
|
||||
gap: 14px;
|
||||
margin: 18px 0;
|
||||
padding: 14px 0;
|
||||
border-top: 1px solid var(--tn-border-subtle);
|
||||
border-bottom: 1px solid var(--tn-border-subtle);
|
||||
}
|
||||
.tn-fact-item {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 4px;
|
||||
}
|
||||
.tn-fact-label {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-fact-value {
|
||||
font-size: 14px;
|
||||
color: var(--tn-text);
|
||||
font-weight: 600;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
.tn-fact-hint {
|
||||
font-size: 11px;
|
||||
color: var(--tn-text-muted);
|
||||
}
|
||||
|
||||
.tn-release-card-actions {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 12px;
|
||||
margin-top: 16px;
|
||||
}
|
||||
|
||||
/* Dialog content styles */
|
||||
.tn-confirm-dialog-content {
|
||||
font-size: 13px;
|
||||
line-height: 1.6;
|
||||
color: var(--tn-text);
|
||||
}
|
||||
.tn-update-safety-tips {
|
||||
margin-top: 10px;
|
||||
padding: 10px 14px;
|
||||
background: #f6f8fb;
|
||||
border-radius: 3px;
|
||||
border: 1px solid var(--tn-border-subtle);
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 4px;
|
||||
}
|
||||
|
||||
.tn-full-notes-modal {
|
||||
margin: 0;
|
||||
padding: 12px;
|
||||
background: #f8fafc;
|
||||
border-radius: 3px;
|
||||
font-size: 13px;
|
||||
line-height: 1.6;
|
||||
color: var(--tn-text);
|
||||
max-height: 50vh;
|
||||
overflow-y: auto;
|
||||
}
|
||||
|
||||
.tn-empty-surface {
|
||||
padding: 36px 20px;
|
||||
text-align: center;
|
||||
}
|
||||
.tn-empty-content {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
color: var(--tn-text-secondary);
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.tn-inline-warning {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
padding: 10px 14px;
|
||||
margin-bottom: 14px;
|
||||
background: #fffbe6;
|
||||
border: 1px solid #ffe58f;
|
||||
border-radius: 3px;
|
||||
color: #d48806;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
/* Responsive adjustments */
|
||||
@media (max-width: 992px) {
|
||||
.tn-update-metrics-grid {
|
||||
grid-template-columns: repeat(2, minmax(0, 1fr));
|
||||
}
|
||||
.tn-facts-grid {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
}
|
||||
@media (max-width: 640px) {
|
||||
.tn-update-metrics-grid {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
.tn-mock-console-header {
|
||||
flex-direction: column;
|
||||
align-items: flex-start;
|
||||
}
|
||||
.tn-release-header {
|
||||
flex-direction: column;
|
||||
}
|
||||
.tn-release-notes-header {
|
||||
align-items: flex-start;
|
||||
flex-direction: column;
|
||||
}
|
||||
.tn-release-notes-header .t-button {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-release-card-actions {
|
||||
flex-direction: column;
|
||||
width: 100%;
|
||||
}
|
||||
.tn-release-card-actions .t-button {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-stepper-wrap {
|
||||
margin-inline: -4px;
|
||||
padding-inline: 4px;
|
||||
}
|
||||
.tn-stepper-wrap .t-steps {
|
||||
min-width: 620px;
|
||||
}
|
||||
.tn-job-runtime-header {
|
||||
align-items: stretch;
|
||||
}
|
||||
.tn-job-status-badge,
|
||||
.tn-speed-indicator {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-speed-indicator {
|
||||
justify-content: flex-start;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user